CREAM Lending Hack

TOTAL LOST $130.0M
Critical Flash Loan Attacks ethereum

What happened

CREAM Finance's Ethereum v1 lending markets were exploited on October 27, 2021 for about $130 million. The attack combined flash liquidity with manipulation of the yUSD vault share price that CREAM's collateral oracle relied on. The attacker made yUSD collateral appear more valuable, then borrowed most available v1 liquidity in one transaction.

Technical Root Cause

CREAM's collateral pricing trusted a manipulable yUSD vault exchange rate, while uncapped recursive supply amplified the resulting collateral value. A direct transfer of underlying tokens to the vault changed pricePerShare and therefore the oracle value used by CREAM. Lending protocols must bound collateral from composable vault shares, use manipulation-resistant pricing, and constrain recursive supply paths that can magnify a transient valuation error.

Case & protocol details

Classification Lending Oracle / Vault Share-Price Manipulation
Protocol Type Lending
Smart Contract Language Solidity
Official Website cream.finance/
Protocol Twitter/X @CreamdotFinance

Attack Timeline

The attacker used two controlled accounts and flash liquidity from MakerDAO and Aave. One account created yUSD and supplied it to CREAM, while the other used ETH collateral to borrow yUSD recursively and send it back, amplifying the first account's recorded crYUSD collateral. The attacker then withdrew Yearn 4-Curve tokens from the yUSD vault and transferred about $8 million of the underlying yCrv back to that vault.

That doubled yUSD's pricePerShare, and CREAM's hybrid oracle doubled the reported value of the collateral. The account could then borrow the remaining liquidity, repay the temporary loans, and retain the difference.

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.